Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtreat

SPLK-1001 Splunk Core Certified User Exam Questions and Answers

Questions 4

Monitor option in Add Data provides _______________.

Options:

A.

Only continuous monitoring.

B.

Only One-time monitoring.

C.

None of the above.

D.

Both One-time and continuous monitoring

Buy Now
Questions 5

You are able to create new Index in Data Input settings.

Options:

A.

No

B.

Yes

Buy Now
Questions 6

Which of the following can be used as wildcard search in Splunk?

Options:

A.

=

B.

>

C.

!

D.

*

Buy Now
Questions 7

Splunk apps are used for following (Choose three.):

Options:

A.

Designed to cater numerous use cases and empower Splunk.

B.

We can not install Splunk App.

C.

Allows multiple workspaces for different use cases/user roles.

D.

It is collection of different Splunk config files like data inputs, UI and Knowledge Object.

Buy Now
Questions 8

Which of the following searches will show the number of categoryld used by each host?

Options:

A.

Sourcetype=access_* |sum bytes by host

B.

Sourcetype=access_* |stats sum(categorylD) by host

C.

Sourcetype=access_* |sum(bytes) by host

D.

Sourcetype=access_* |stats sum by host

Buy Now
Questions 9

Parsing of data can happen both in HF and UF.

Options:

A.

Yes

B.

No

Buy Now
Questions 10

Fields are searchable name and value pairings that differentiates one event from another.

Options:

A.

False

B.

True

Buy Now
Questions 11

Which of the following is true about user account settings and preferences?

Options:

A.

Search & Reporting is the only app that can be set as the default application.

B.

Full names can only be changed by accounts with a Power User or Admin role.

C.

Time zones are automatically updated based on the setting of the computer accessing Splunk.

D.

Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.

Buy Now
Questions 12

When is an alert triggered?

Options:

A.

When Splunk encounters a syntax error in a search

B.

When a trigger action meets the predefined conditions

C.

When an event in a search matches up with a data model

D.

When results of a search meet a specifically defined condition

Buy Now
Questions 13

How are the results of the following search sorted?

… | sort action, —file, +bytes

Options:

A.

In descending order by action, then descending order by file, and lastly by ascending order of bytes.

B.

In ascending order by action, then descending order by file, and lastly by ascending order of bytes.

C.

In descending order by action if it exists. If not, then in descending order by file, and if both action and file do not exist, by ascending order of bytes.

D.

In ascending order by action if it exists. If not, then in descending order by file, and if both action and file do not exist, by ascending order of bytes.

Buy Now
Questions 14

How can another user gain access to a saved report?

Options:

A.

The owner of the report can edit permissions from the Edit dropdown

B.

Only users with an Admin or Power User role can access other users' reports

C.

Anyone can access any reports marked as public within a shared Splunk deployment

D.

The owner of the report must clone the original report and save it to their user account

Buy Now
Questions 15

Which of the following are common constraints of the top command?

Options:

A.

limit, count

B.

limit, showpercent

C.

limits, countfield

D.

showperc, countfield

Buy Now
Questions 16

What is Splunk?

Options:

A.

Splunk is a software platform to search, analyze and visualize the machine-generated data.

B.

Database management tool.

C.

Security Information and Event Management (SIEM).

D.

Cloud based application that help in analyzing logs.

Buy Now
Questions 17

Zoom Out and Zoom to Selection re-executes the search.

Options:

A.

No

B.

Yes

Buy Now
Questions 18

What will always appear in the Selected Fields list?

Options:

A.

index

B.

action

C.

clientip

D.

sourcetype

Buy Now
Questions 19

Which of the following are Splunk premium enhanced solutions? (Choose three.)

Options:

A.

Splunk User Behavior Analytics (UBA)

B.

Splunk IT Service Intelligence (ITSI)

C.

Splunk Enterprise Security (ES)

D.

Splunk Analytics Security (AS)

Buy Now
Questions 20

Log filtering/parsing can be done from _____________.

Options:

A.

Index Forwarders (IF)

B.

Universal Forwarders (UF)

C.

Super Forwarder (SF)

D.

Heavy Forwarders (HF)

Buy Now
Questions 21

When viewing results of a search job from the Activity menu, which of the following is displayed?

Options:

A.

New events based on the current time range picker

B.

The same events based on the current time range picker

C.

The same events from when the original search was executed

D.

New events in addition to the same events from the original search

Buy Now
Questions 22

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

Options:

A.

True

B.

False

Buy Now
Questions 23

What does the stats command do?

Options:

A.

Automatically correlates related fields

B.

Converts field values into numerical values

C.

Calculates statistics on data that matches the search criteria

D.

Analyzes numerical fields for their ability to predict another discrete field

Buy Now
Questions 24

Assuming a user has the capability to edit reports, which of the following are editable?

Options:

A.

Acceleration, schedule, permissions

B.

The report’s name, schedule, permissions

C.

The report’s name, acceleration, schedule

D.

The report’s name, acceleration, permissions

Buy Now
Questions 25

Prefix wildcards might cause performance issues.

Options:

A.

False

B.

True

Buy Now
Questions 26

Query - status != 100:

Options:

A.

Will return event where status field exist but value of that field is not 100.

B.

Will return event where status field exist but value of that field is not 100 and all events where status field

doesn't exist.

C.

Will get different results depending on data

Buy Now
Questions 27

Forward Option gather and forward data to indexers over a receiving port from remote machines.

Options:

A.

False

B.

True

Buy Now
Questions 28

Machine data can be in structured and unstructured format.

Options:

A.

False

B.

True

Buy Now
Questions 29

Which of the following fields is stored with the events in the index?

Options:

A.

user

B.

source

C.

location

D.

sourcelp

Buy Now
Questions 30

This function of the stats command allows you to return the middle-most value of field X.

Options:

A.

Median(X)

B.

Eval by X

C.

Fields(X)

D.

Values(X)

Buy Now
Questions 31

Snapping rounds down to the nearest specified unit.

Options:

A.

Yes

B.

No

Buy Now
Questions 32

Splunk automatically determines the source type for major data types.

Options:

A.

False

B.

True

Buy Now
Questions 33

Matching of parentheses is a feature of Splunk Assistant.

Options:

A.

No

B.

Yes

Buy Now
Questions 34

Which time range picker configuration would return real-time events for the past 30 seconds?

Options:

A.

Preset - Relative: 30-seconds ago

B.

Relative - Earliest: 30-seconds ago, Latest: Now

C.

Real-time - Earliest: 30-seconds ago, Latest: Now

D.

Advanced - Earliest: 30-seconds ago, Latest: Now

Buy Now
Questions 35

Lookups allow you to overwrite your raw event.

Options:

A.

True

B.

False

Buy Now
Questions 36

Select the statements that are true for timeline in Splunk (Choose four.):

Options:

A.

Timeline shows distribution of events specified in the time range in the form of bars.

B.

Single click to see the result for particular time period.

C.

You can click and drag across the bar for selecting the range.

D.

This is default view and you can't make any changes to it.

E.

You can hover your mouse for details like total events, time and date.

Buy Now
Questions 37

When is the pipe character, I, used in search strings?

Options:

A.

Before clauses. For example: stats sum(bytes) | by host

B.

Before commands. For example: | stats sum(bytes) by host

C.

Before arguments. For example: stats sum| (bytes) by host

D.

Before functions. For example: stats |sum(bytes) by host

Buy Now
Questions 38

Which component of Splunk let us write SPL query to find the required data?

Options:

A.

Forwarders

B.

Indexer

C.

Heavy Forwarders

D.

Search head

Buy Now
Questions 39

Will the queries following below get the same result?

1. index=log sourcetype=error_log status !=100

2. index=log sourcetype=error_log NOT status =100

Options:

A.

Yes

B.

No

Buy Now
Questions 40

According to Splunk best practices, which placement of the wildcard results in the most efficient search?

Options:

A.

f*il

B.

*fail

C.

fail*

D.

*fail*

Buy Now
Questions 41

What result will you get with following search index=test sourcetype="The_Questionnaire_P*" ?

Options:

A.

the_questionnaire _pedia

B.

the_questionnaire pedia

C.

the_questionnaire_pedia

D.

the_questionnaire Pedia

Buy Now
Questions 42

Which of the following Splunk components typically resides on the machines where data originates?

Options:

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Buy Now
Questions 43

Which of the following searches will return results where fail, 400, and error exist in every event?

Options:

A.

error AND (fail AND 400)

B.

error OR (fail and 400)

C.

error AND (fail OR 400)

D.

error OR fail OR 400

Buy Now
Questions 44

When a Splunk search generates calculated data that appears in the Statistics tab. in what formats can the results be exported?

Options:

A.

CSV, JSON, PDF

B.

CSV, XML JSON

C.

Raw Events, XML, JSON

D.

Raw Events, CSV, XML, JSON

Buy Now
Questions 45

Splunk indexes the data on the basis of timestamps.

Options:

A.

True

B.

False

Buy Now
Questions 46

The better way of writing search query for index is:

Options:

A.

index=a index=b

B.

(index=a OR index=b)

C.

index=(a & b)

D.

index = a, b

Buy Now
Questions 47

Which command is used to validate a lookup file?

Options:

A.

| lookup products.csv

B.

inputlookup products.csv

C.

I inputlookup products.csv

D.

| lookup definition products.csv

Buy Now
Questions 48

Given the following SPL search, how many rows of results would you expect to be returned by default? index=security sourcetype=linux_secure (fail* OR invalid) I top src__ip

Options:

A.

10

B.

50

C.

100

D.

20

Buy Now
Questions 49

This search will return 20 results. SEARCH: error | top host limit = 20

Options:

A.

True

B.

False

Buy Now
Questions 50

Which of the following is the best way to create a report that shows the last 24 hours of events?

Options:

A.

Use earliest=-1d@d latest=@d

B.

Set a real-time search over a 24-hour window

C.

Use the time range picket to select “Yesterday”

D.

Use the time range picker to select “Last 24 hours”

Buy Now
Questions 51

Which command will rename action to Customer Action?

Options:

A.

| rename action = CustomerAction

B.

| rename Action as “Customer Action”

C.

| rename Action to “Customer Action”

D.

| rename action as “Customer Action”

Buy Now
Questions 52

Which of the statements is correct regarding click and drag option in timeline?

Options:

A.

The new result after selecting the range by dragging filters the events and displays the most recent first.

B.

There is no functionality like click and drag in Splunk's timeline.

C.

Using this option executes a new query.

D.

This doesn't execute a new query

Buy Now
Questions 53

How many main user roles do you have in Splunk?

Options:

A.

2

B.

4

C.

1

D.

3

Buy Now
Questions 54

Which statement is true about the top command?

Options:

A.

It returns the top 10 results

B.

It displays the output in table format

C.

It returns the count and percent columns per row

D.

All of the above

Buy Now
Questions 55

Which search string returns a filed containing the number of matching events and names that field Event Count?

Options:

A.

index=security failure | stats sum as “Event Count”

B.

index=security failure | stats count as “Event Count”

C.

index=security failure | stats count by “Event Count”

D.

index=security failure | stats dc(count) as “Event Count”

Buy Now
Questions 56

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

Options:

A.

True

B.

False

Buy Now
Questions 57

Which of the following represents the Splunk recommended naming convention for dashboards?

Options:

A.

Description_Group_Object

B.

Group_Description_Object

C.

Group_Object_Description

D.

Object_Group_Description

Buy Now
Questions 58

When looking at a dashboard panel that is based on a report, which of the following is true?

Options:

A.

You can modify the search string in the panel, and you can change and configure the visualization.

B.

You can modify the search string in the panel, but you cannot change and configure the visualization.

C.

You cannot modify the search string in the panel, but you can change and configure the visualization.

D.

You cannot modify the search string in the panel, and you cannot change and configure the visualization.

Buy Now
Questions 59

Which stats command function provides a count of how many unique values exist for a given field in the result set?

Options:

A.

dc(field)

B.

count(field)

C.

count-by(field)

D.

distinct-count(field)

Buy Now
Questions 60

Which of the following is a Splunk internal field?

Options:

A.

_raw

B.

host

C.

_host

D.

index

Buy Now
Questions 61

What type of search can be saved as a report?

Options:

A.

Any search can be saved as a report

B.

Only searches that generate visualizations

C.

Only searches containing a transforming command

D.

Only searches that generate statistics or visualizations

Buy Now
Questions 62

When displaying results of a search, which of the following is true about line charts?

Options:

A.

Line charts are optimal for single and multiple series.

B.

Line charts are optimal for single series when using Fast mode.

C.

Line charts are optimal for multiple series with 3 or more columns.

D.

Line charts are optimal for multiseries searches with at least 2 or more columns.

Buy Now
Questions 63

After running a search, what effect does clicking and dragging across the timeline have?

Options:

A.

Executes a new search.

B.

Filters current search results.

C.

Moves to past or future events.

D.

Expands the time range of the search.

Buy Now
Questions 64

Which of the following searches would return only events that match the following criteria?

• Events are inside the main index

• The field status exists in the event

• The value in the status field does not equal 200

Options:

A.

index==main status!==200

B.

index=main NOT status=200

C.

index==main NOT status==200

D.

index-main status!=200

Buy Now
Questions 65

In the fields sidebar, what indicates that a field is numeric?

Options:

A.

A number to the right of the field name.

B.

A # symbol to the left of the field name.

C.

A lowercase n to the left of the field name.

D.

A lowercase n to the right of the field name.

Buy Now
Questions 66

Which is a primary function of the timeline located under the search bar?

Options:

A.

To differentiate between structured and unstructured events in the data

B.

To sort the events returned by the search command in chronological order

C.

To zoom in and zoom out. although this does not change the scale of the chart

D.

To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Buy Now
Questions 67

What does the values function of the stats command do?

Options:

A.

Lists all values of a given field.

B.

Lists unique values of a given field.

C.

Returns a count of unique values for a given field.

D.

Returns the number of events that match the search.

Buy Now
Questions 68

Which of the following is the appropriately formatted SPL search?

Options:

A.

index=security sourcetype=linux secure (invalid OR failed) | stats count as

"Potential Issues"

B.

index=security sourcetype=linux secure (invalid OR failed) | stats as

"Potential Issues"

C.

index—security sourcetype=linux secure (invalid OR failed) | count stats as

"Potential Issues"

D.

index—security sourcetype=linux secure (invalid OR failed) | count as "Potential Issues"

Buy Now
Questions 69

At index time, in which field does Splunk store the timestamp value?

Options:

A.

time

B.

_time

C.

EventTime

D.

timestamp

Buy Now
Questions 70

What is the primary use for the rare command?

Options:

A.

To sort field values in descending order.

B.

To return only fields containing five of fewer values.

C.

To find the least common values of a field in a dataset.

D.

To find the fields with the fewest number of values across a dataset.

Buy Now
Questions 71

Which of the following is the recommended way to create multiple dashboards displaying data from the same search?

Options:

A.

Save the search as a report and use it in multiple dashboards as needed

B.

Save the search as a dashboard panel for each dashboard that needs the data

C.

Save the search as a scheduled alert and use it in multiple dashboards as needed

D.

Export the results of the search to an XML file and use the file as the basis of the dashboards

Buy Now
Questions 72

Portal for Splunk apps can be accessed through www.splunkbase.com

Options:

A.

False

B.

True

Buy Now
Questions 73

At the time of searching the start time is 03:35:08.

Will it look back to 03:00:00 if we use -30m@h in searching?

Options:

A.

Yes

B.

No

Buy Now
Exam Code: SPLK-1001
Exam Name: Splunk Core Certified User Exam
Last Update: May 18, 2024
Questions: 244
SPLK-1001 pdf

SPLK-1001 PDF

$28  $80
SPLK-1001 Engine

SPLK-1001 Testing Engine

$33.25  $95
SPLK-1001 PDF + Engine

SPLK-1001 PDF + Testing Engine

$45.5  $130